# Microsoft warns of passkey-themed identity phishing campaign

> Microsoft said social engineering that impersonates passkey registration and single sign-on can compromise employee identities and cloud accounts.

- Canonical URL: https://newsverum.com/en/news/microsoft-passkey-themed-social-engineering-campaign-2026
- Publisher: Newsverum
- Section: Security
- Published: 2026-10-06T08:59:01+00:00
- Updated: 2026-10-07T00:55:47+03:00
- Event / data period: 2026-05
- Other editions: [Türkçe](https://newsverum.com/tr/news/microsoft-passkey-themed-social-engineering-campaign-2026.md), [العربية](https://newsverum.com/ar/news/microsoft-passkey-themed-social-engineering-campaign-2026.md), [Français](https://newsverum.com/fr/news/microsoft-passkey-themed-social-engineering-campaign-2026.md), [Español](https://newsverum.com/es/news/microsoft-passkey-themed-social-engineering-campaign-2026.md), [Deutsch](https://newsverum.com/de/news/microsoft-passkey-themed-social-engineering-campaign-2026.md), [Português](https://newsverum.com/pt/news/microsoft-passkey-themed-social-engineering-campaign-2026.md)

Microsoft Threat Intelligence described on 9 September 2026 a global social-engineering campaign that impersonated passkey enrollment and single sign-on. The company said multiple threat actors used email and voice communications to direct employees toward identity compromise and access to Microsoft 365 cloud services.

Microsoft advised organisations to correlate unusual sign-ins with new authentication-method registrations, Microsoft Graph reconnaissance and high-volume file downloads. Its assessment attributes activity to several threat clusters; it does not say that every campaign step occurred in every incident.

## Data

### Security development

Security event or institutional action reported by the source.

Methodology: The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

| date | label | description | status |
|---|---|---|---|
| 2026-09-09 | Microsoft disclosed a passkey-themed social engineering campaign | The company said attackers used passkey- and single-sign-on-themed messages to target employees and pursue account access and cloud data. | occurred |

Sources: <https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/> · Download data: [JSON](https://newsverum.com/api/v1/articles/microsoft-passkey-themed-social-engineering-campaign-2026/data/security-event?lang=en&format=json) · [CSV](https://newsverum.com/api/v1/articles/microsoft-passkey-themed-social-engineering-campaign-2026/data/security-event?lang=en&format=csv)

## Sources

- [Microsoft Threat Intelligence](<https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/>) (Source checked: 2026-10-06; Published: 2026-09-09)

## Correction history

- 2026-10-07T00:55:47+03:00: German and Portuguese editions and translations of the data and correction explanations have been added to this article.

---

Cite the canonical URL above. [Editorial standards and corrections](https://newsverum.com/en/editorial)
